The demand that hasn’t called yet Log in
getfishnet
Test my eligibility

Change your language and country?

You are currently viewing the Switzerland version, in English. Another version may be better suited to your situation.

Stay on this version Change version
Market reading · assurance courtage

Operational resilience after March 2025: where is the next evidence gap hiding?

How insurers, brokers and resilience advisers can turn the post-2025 operating-resilience cycle into a bounded review and recurring evidence service.

getfishnetDocumented analysis20269 min read

A claims portal returns in forty minutes, yet vulnerable customers wait two days for a manual workaround. A cloud supplier passes its own test, yet nobody can show how the insurer’s customer service stays within tolerance when the dependency fails. Those are not technology anecdotes. They are decision gaps with an owner, evidence and a commercial consequence. The 31 March 2025 milestone required firms in scope to complete the mapping and testing needed to remain within impact tolerances for each important business service. It did not close the market. It moved the buying question from “Are we ready for the deadline?” to “Can the board still prove this service works after the last product, supplier, incident or operating-model change?” This reading explains who is in scope, how to distinguish a customer service from its systems, what a useful review should deliver, and how an adviser can turn recurring evidence gaps into a bounded first engagement and an ongoing resilience service.

What changed when the March 2025 transition period ended?

The March 2025 milestone changed operational resilience from a remediation programme into a continuing operating discipline. In-scope firms had to complete sufficient mapping and testing, make the necessary investment and show that each important business service could remain within its impact tolerance during severe but plausible disruption. Annual and material-change reviews continue after the date.

The Financial Conduct Authority describes operational resilience as the ability to prevent, adapt, respond to, recover and learn from disruption. Its March 2026 observations show why the deadline did not finish the work: services, tolerances, maps, scenarios and vulnerabilities must evolve with incidents and business change. The Prudential Regulation Authority’s SS1/21 applies the same service-led logic to relevant insurers while preserving prudential outcomes such as safety, soundness and policyholder protection.

The practical trigger is therefore not a regulation alone. It is a changed claim journey, product, customer group, location, outsourcing arrangement, system release, acquisition or incident that makes yesterday’s evidence unreliable.

The post-2025 resilience cycleThe post-2025 resilience cycle
  1. 1Define the customer or market outcome
  2. 2Set the point of intolerable disruption
  3. 3Map people, process, technology, facilities, information and third parties
  4. 4Test severe but plausible disruption
  5. 5Fund and verify remediation
  6. 6Reassess after incidents and material change

Which insurers and brokers are actually in scope?

FCA operational-resilience rules cover specified firms including insurers, while PRA expectations cover relevant dual-regulated insurers. Insurance intermediaries can fall within scope when they meet the enhanced-scope SM&CR definition. A broker outside that perimeter may still face resilience requirements through contracts, delegated authority, customer-outcome duties or an insurer’s dependency mapping.

The FCA’s insurance observations make the distinction explicit: Solvency II insurers are in scope, and intermediaries may be in scope according to their regulatory category. That means a campaign cannot begin with a list labelled “insurance”. It must qualify legal entity, permission, group role, regulated perimeter and the service the organisation actually delivers.

For advisers, the adjacent market is often larger than the directly regulated one. Claims administrators, cloud providers, call centres, data processors, loss adjusters and delegated partners may supply a resource that determines whether an insurer remains within tolerance. The offer must still be framed as evidence and operating support—not as a guarantee of regulatory compliance.

Which business service should be reviewed first?

The first review should focus on a service whose disruption can create intolerable customer harm or threaten market integrity, and where a recent change has weakened the evidence. Claims payment, emergency assistance, policy access, renewal or complaint handling can qualify; an application, team or supplier is normally a supporting resource rather than the service itself.

A strong service statement names the customer, the outcome and the start and end of delivery. “Claims platform availability” is too technical. “A retail customer can notify and progress an urgent claim” can be tested across channels, people, data and suppliers. The FCA has repeatedly warned against treating internal processes as important business services without connecting them to external harm.

The most useful acquisition signals are observable: a platform migration, outsourced claims contract, new product line, acquisition, major incident, board review or repeated customer-service failure. They create a reason to examine one service now, rather than sell a broad transformation with no boundary.

How should an impact tolerance differ from a recovery target?

An impact tolerance marks the maximum disruption an important business service can sustain before consumer harm or market impact becomes intolerable. A recovery time objective is an internal recovery target for a system or process. Recovery may need to occur earlier because backlogs, vulnerable customers and manual work continue to generate harm after technology returns.

Time is often necessary but not sufficient. The FCA’s 2024 and 2026 observations encourage clearer rationales and quantitative measures such as transaction volumes or financial thresholds alongside time. An insurer might therefore monitor elapsed time, unprocessed urgent claims, customers without an alternative route and value awaiting payment.

The review should record the rationale, assumptions, customer segments and approval trail. A short tolerance is not automatically prudent, and a long one is not automatically realistic. The question is whether the threshold reflects the harm and can be demonstrated under stress.

MeasureQuestion answeredTypical owner
Impact toleranceWhen does disruption become intolerable?governing body
Recovery time objectiveWhen must a resource be restored?technology or process owner
Backlog thresholdHow much unfinished work can be recovered safely?service owner
Vulnerability measureWhat could prevent the service staying within tolerance?resilience lead

What must end-to-end mapping reveal?

End-to-end mapping must reveal the people, processes, technology, facilities, information and third parties needed to deliver the important service. It should connect each dependency to a failure mode, workaround, owner and recovery evidence. A system inventory alone misses decisions and manual operations; an exhaustive asset catalogue can hide the few dependencies that determine the outcome.

The FCA’s latest observations praise clear methodology, multiple data sources, ownership and the use of mapping to guide testing. They also identify persistent weaknesses: maps remain too technology-centred, third-party vulnerabilities are incompletely assessed and ownership data becomes stale.

A bounded review can begin with one real customer journey and trace it backwards. For an urgent claim, that may include notification channels, identity data, coverage decisions, specialist suppliers, payment rails, communications and manual alternatives. Every dependency should answer a simple question: if this fails, what happens to the customer clock?

What makes scenario testing commercially useful rather than ceremonial?

Scenario testing becomes useful when it challenges the firm’s ability to remain within tolerance, records customer impact and forces a decision about workarounds, investment or accepted exposure. The scenario must be severe but plausible, vary in nature and duration, and connect directly to mapped vulnerabilities. Completing a tabletop agenda is not evidence that the service survived.

Useful scenarios can combine cloud-region failure, cyber compromise, data corruption, workforce loss, supplier collapse or simultaneous disruption. They state what is unavailable, when the clock starts, which customer groups are affected, what information decision-makers receive and what counts as recovery.

The output is not simply a red or green score. It is a timed evidence trail: decisions made, workaround capacity, backlog, communications, breach point, vulnerabilities and funded actions. Retesting closes the loop. The FCA expects remediation to be approved, funded, governed and evidenced at closure rather than left as an aspirational roadmap.

A test should move evidence toward a funded decisionA test should move evidence toward a funded decision
  • Étape 1D00: inject the disruption and start the customer clock
  • Étape 2D01: activate ownership, alternatives and communications
  • Étape 3D02: compare harm and backlog with tolerance
  • Étape 4W01: approve remediation or record accepted exposure
  • Étape 5W06: retest the changed service and close evidence

Where does third-party risk create a buying window?

A third-party buying window appears when an insurer cannot connect a supplier’s controls to its own important business service and tolerance. Certification, uptime or a generic disaster-recovery test may describe the supplier, but they do not prove the insurer’s customer outcome. Contract renewal, concentration, outsourcing change and repeated incidents make the evidence gap commercially actionable.

The review should connect service, supplier component, data, tolerance, test participation, incident information, exit path and substitute capacity. The firm remains responsible for its resilience even when delivery is outsourced. For the supplier, this creates a product opportunity: provide service-specific evidence packs and joint scenario participation instead of sending the same assurance document to every client.

Move from supplier assurance to customer-service evidenceMove from supplier assurance to customer-service evidence
  • Étape 1Insurer: important service, tolerance, accountable owner
  • Étape 2Supplier: component, failure mode, recovery and test evidence
  • Étape 3Joint: incident clock, workaround, communications and exit

What should a paid resilience evidence review deliver?

A paid resilience evidence review should examine one important service and produce an agreed service statement, tolerance rationale, dependency map, scenario design, evidence gaps and prioritised remediation decisions. It should be small enough to buy without a transformation programme and rigorous enough to support board challenge, supplier action and the next testing cycle.

A ten-to-fifteen-working-day engagement can request the service definition, current tolerance, last map, supplier evidence, incident history, scenario results and self-assessment extract. The adviser classifies gaps by customer consequence and decision readiness. Regulated judgements remain with the competent firm and its advisers; the acquisition partner does not certify resilience.

The recurring service follows material change and the annual review cycle: refresh the map, update scenarios, examine live incidents, track remediation and prepare the evidence trail. Recurrence comes from an operating need, not from extending a diagnostic that no longer adds value.

How can a multichannel campaign find firms with a live resilience trigger?

A resilience campaign should target the combination of an in-scope or dependent organisation, an important service and a recent change. Search captures declared needs; specialist content and events build recognition; partner networks expose supplier and governance triggers; email, telephone and account research verify ownership, timing and available evidence before a meeting is accepted.

The campaign starts with several hypotheses, not one channel. Search themes can focus on impact-tolerance review, scenario testing and third-party mapping. Broker and insurance networks can surface renewals or operating changes. Direct research can identify platform migrations, outsourcing, acquisitions and public incidents. Calls and emails should qualify the service and decision, not imply that the recipient is non-compliant.

Non-exhaustive campaign workflow over twelve weeksNon-exhaustive campaign workflow over twelve weeks
  1. 1Étape 1
  2. 2Étape 2
  3. 3Étape 3
  4. 4Étape 4
  5. 5Étape 5

Which numbers decide whether the campaign should scale?

The scale decision should use qualified cases, first-purchase conversion, expert effort, attributable acquisition cost and maintained recurring revenue—not impressions or meetings alone. Channel mix matters only when it is correlated with the service trigger, evidence quality and value retained after delivery. A high-volume channel can lose budget when it repeatedly produces unserviceable cases.

The table below is a planning model for a test cohort, not a disclosure of client performance. It shows the type of decision the campaign must support.

A pivot is justified when the same rejection repeats. No identifiable important service means the segmentation is too broad. No access to evidence means the first purchase is badly designed or the buyer is wrong. Strong demand but slow delivery means the partner must narrow scope, improve intake or add expert capacity before media spend increases.

Channel familyQualified casesFirst reviewsMaintained monthly value
Search and specialist content144£6
Networks and referral partners115£9
Email and telephone qualification184£7
Named-account research73£6

What must the insurance partner provide before acquisition accelerates?

The insurance or resilience partner must provide a defensible service scope, named expert owner, evidence request, qualification rules, response times, capacity and a safe boundary for regulated conclusions. It must also explain how a successful first review becomes remediation, retesting or recurring monitoring without forcing every customer into the same programme.

The minimum operating pack includes one offer page, eligible and excluded profiles, discovery questions, document list, pricing logic, handoff owner, conflict and confidentiality rules, and weekly feedback on accepted and rejected cases. Rapid feedback is essential: GetFishNet can test angles quickly only when the partner explains why a case progressed, stalled or should never have entered the pipeline.

Our role is to identify the market opportunity, build and operate the multichannel acquisition system, measure the economics and move budget toward qualified, maintainable demand. The partner’s role is to make the service true: review the evidence, own specialist judgements, deliver the first purchase and maintain the relationship through useful recurring work.

Which authorities support this reading and what remains outside it?

This reading relies on the Financial Conduct Authority’s operational-resilience rules, insurance-sector observations and 2024–2026 good-practice findings, together with the Prudential Regulation Authority’s SS1/21. It does not determine whether a specific entity or service is in scope, approve an impact tolerance, certify a supplier or promise regulatory, operational or commercial outcomes.

The authoritative entities cited are the Financial Conduct Authority, its PS21/3 policy statement and operational-resilience observations, and the Prudential Regulation Authority’s supervisory statement SS1/21. Their public guidance should be checked again when a live dossier begins because reporting rules, supervisory observations and firm circumstances continue to change.

Related readings remain dynamic. They should connect this analysis to DORA, cyber incident reporting, insurance distribution and third-party governance only when the published route adds a genuine next step for the reader.

Does your market present a comparable window?

The eligibility report dates and quantifies it, then tests whether it deserves action.

Test my eligibility
Strategic development · non-exhaustive demonstration

Reading the diagram. A disease contact only progresses after proof of origin, qualification of the relationship and control of the product concerned.

Text alternative. Telephone, prescriber or incoming request follow different proofs; missing consent causes documented exit.

How can the testing cycle reach a stable operating rhythm?

Relative benchmarks: D00 sets the rules of origin and termination of contact, D14 closes the preparation, W03 to W06 tests the scripts, consents, relationships of more than thirty-six months and ceilings per product, W07 to W08 arbitrator, then M03 stabilizes documented paths. Variances are recorded before any budget extension.

Gantt chart for the testing cycle — NON-EXHAUSTIVE DEMONSTRATION

getfishnet analysis diagram — non-exhaustive representation.

Reading the diagram. The foundation secures the right to contact; exploration then measures the quality of requests before any channel stabilization.

Textual alternative. D00 sets consent, D14 audits scripts, W03–W06 tests provenance, W07–W08 cuts discrepancies, M03 maintains compliance.

What financial potential does the model make visible?

Model: 132 qualified conversations, 44 reviews and 26 new customers. Weighted average: 1 527 CHF; monthly total: 39 700 CHF. The projection concerns acquisitions agreed and allocated, without using the ceilings as margin or portfolio value. No national denominator is applied.

Breakdown of acquisitions — NON-EXHAUSTIVE DEMONSTRATION

The chart counts customers, not percentage points.

getfishnet analysis diagram — non-exhaustive representation.

Reading the diagram. 26 acquisitions represent subscriptions preceded by a controlled origin and relationship; the size of a share does not prejudge either the documentary quality or the maintained value.

Text alternative. The circle distributes customers obtained after verifiable consent, never people simply called. Total: 26 customers, reread with the value specific to each channel.

How do customers, average monthly revenue, and recurring revenue correlate by channel?

Channel exploredCustomersAverage monthly revenue per customerMonthly Recurring Channel Revenue
Natural and paid referencing41 300 CHF5 200 CHF
Telephone outreach31 600 CHF4 800 CHF
Voicemails2900 CHF1 800 CHF
Email Campaigns41 200 CHF4 800 CHF
Social networks31 400 CHF4 200 CHF
Partners and prescribers32 000 CHF6 000 CHF
Events and webinars21 700 CHF3 400 CHF
Advertising retargeting11 100 CHF1 100 CHF
Strategic accounts and outbound outreach22 300 CHF4 600 CHF
Content and press relations21 900 CHF3 800 CHF
Total / weighted average261 527 CHF39 700 CHF

The value is read again with the product, the applicable ceiling and the cost of controlling the provenance. The product customers × average income totals 39 700 CHF without promising performance.

Monthly recurring revenue by channel — NON-EXHAUSTIVE DEMONSTRATION

getfishnet analysis diagram — non-exhaustive representation.

Reading the diagram. Compliant disease contacts, their converted volumes and the corresponding monthly income recompose 39 700 CHF without a value outside the table.

Alternative text. Each height associates an authorized channel, actual assigned customers, and the value specific to their product. Their addition exactly equals monthly 39 700 CHF.

How should acquisition cost be assessed before recurring revenue is scaled?

Arbitration adds proof of consent, script control, relationship data, call supervision and refusal handling and reports the charge to assigned customers. It compares legal origin, product concerned, ceiling, full cost, expected termination and service capacity then reduces any channel that weakens the proof.

Funnel to Retained Monthly Recurring Revenue — NON-EXHAUSTIVE DEMONSTRATION

getfishnet analysis diagram — non-exhaustive representation.

Reading the diagram. disease contacts whose origin is demonstrated produce raw 39 700 CHF, then 34 142 CHF after maintaining at 86 %.

Text alternative. 132 conversations become 44 journals and 26 clients for disease contacts whose provenance is demonstrated. 39 700 CHF weighted to 86 % gives 34 142 CHF.

Financial limit. The 70 francs and the sixteen bonuses limit the remuneration; they give neither margin, nor number of contracts, nor maintenance. The 34 142 CHF remains a hypothesis, without reference value or forecast.

Text references: Federal Office of Public Health, decision and rules applicable to intermediaries; monitoring activity report. The federal office describes ceilings and outreach, while consent and history remain evidence specific to the file. The addresses remain in the internal source register. Each topic retains a clear documentary boundary.

The ISA 2024 processes the status. The ICA 2022 processes the contract trace. The nLPD 2023 shows another prequalification of the contact and data.

CORRELATED READINGS — DYNAMIC MODULE

The thematic map will link rules 2024 of health insurance intermediaries to ISA for status, ICA for contract and nLPD for legality of contact data. The links remain governed without implying equivalence.

The September deadline has passed; each origin of contact must always be able to be explained The report isolates the proof and the next action without reopening the 2024 rules of health insurance intermediaries.

g
getfishnet editorial team

The topic is broken down into entities, attributes, evidence, channels, costs and decision points. Institutions are cited in the text; no external resource interrupts the reading path.

documented

All market readings.

Could one resilience evidence gap open your next acquisition window?

GetFishNet will conduct a 100% free eligibility test to compare your current acquisition pain points, offer, market triggers and delivery capacity. If real development synergies exist, we will design a tailored multichannel strategy for a bounded first purchase and recurring client value.

Test my eligibility for free
Test d'éligibilité

Vérifions votre marché.

Dossier reçu.

Nous étudions votre marché et rendons le verdict sous 48 heures.

Fermer

Deux minutes. Verdict sous 48 heures, sans engagement.

Vérifier mon éligibilité